CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,261 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 28 of 126
- CVE-2020-11956CRITICALCVSS 9.8EG 9.82020-07-14
An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a least privilege violation.
- CVE-2020-11963CRITICALCVSS 9.8EG 9.82020-04-21
IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new net…
- CVE-2020-11978CRITICALCVSS 8.8EG 9.0⚠ KEV2020-07-17
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary command…
- CVE-2020-11981CRITICALCVSS 9.8EG 9.82020-07-17
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbi…
- CVE-2020-12078HIGHCVSS 8.8EG 8.82020-04-28
An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (interna…
- CVE-2020-12107CRITICALCVSS 9.8EG 9.82020-08-12
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System.
- CVE-2020-12109CRITICALCVSS 8.8EG 9.02020-05-04
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build…
- CVE-2020-12111HIGHCVSS 8.8EG 8.82020-05-04
Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
- CVE-2020-12124CRITICALCVSS 9.8EG 9.82020-10-02
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.
- CVE-2020-12148MEDIUMCVSS 6.8EG 6.82020-12-11
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance.…
- CVE-2020-12149MEDIUMCVSS 6.8EG 6.82020-12-11
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the res…
- CVE-2020-12242HIGHCVSS 7.8EG 7.82020-04-27
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account.
- CVE-2020-12246HIGHCVSS 8.8EG 8.82020-04-29
Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslookup nslookup_ipaddr parameter, or the Traceroute traceroute_ipaddr parameter.
- CVE-2020-12393HIGHCVSS 7.8EG 7.82020-05-26
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could ha…
- CVE-2020-12513HIGHCVSS 7.5EG 7.52021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
- CVE-2020-12522CRITICALCVSS 10.0EG 10.02020-12-17
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Sta…
- CVE-2020-12620HIGHCVSS 7.8EG 7.82020-07-30
Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after an IP address).
- CVE-2020-12641CRITICALCVSS 9.8EG 9.8⚠ KEV2020-05-04
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
- CVE-2020-12774HIGHCVSS 8.2EG 8.22020-07-22
D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.
- CVE-2020-12775CRITICALCVSS 9.8EG 9.82022-03-01
Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execut…
- CVE-2020-13122HIGHCVSS 8.8EG 8.82020-08-17
The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destination ipaddr" command. This could be used by a read-only us…
- CVE-2020-13124HIGHCVSS 8.8EG 8.82020-08-11
SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on the underlying operating system.
- CVE-2020-13151CRITICALCVSS 9.8EG 9.82020-08-05
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, …
- CVE-2020-13159CRITICALCVSS 9.8EG 9.82020-06-22
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.
- CVE-2020-13167CRITICALCVSS 9.8EG 9.82020-05-19
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.
- CVE-2020-13252HIGHCVSS 8.8EG 8.82020-05-21
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayService…
- CVE-2020-13378HIGHCVSS 8.8EG 8.82023-05-12
Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arbitrary code.
- CVE-2020-13388CRITICALCVSS 9.8EG 9.82020-05-22
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resul…
- CVE-2020-13404HIGHCVSS 8.8EG 8.82020-08-05
The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
- CVE-2020-13448HIGHCVSS 8.8EG 8.82020-06-01
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
- CVE-2020-13619CRITICALCVSS 9.8EG 9.82020-07-01
php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
- CVE-2020-13694HIGHCVSS 8.8EG 8.82020-06-01
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can execute arbitrary OS commands via the mysql -e option.
- CVE-2020-13712HIGHCVSS 7.8EG 7.82024-12-20
A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or earlier is affected. MG90 running MGOS 4.2.1 or earlier is affected.
- CVE-2020-13778HIGHCVSS 8.8EG 8.82020-10-19
rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplate.php or lib/ajaxHandlers/ajaxEditTemplate.php.
- CVE-2020-13782HIGHCVSS 8.8EG 8.82020-06-03
D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.
- CVE-2020-13802CRITICALCVSS 9.8EG 9.82020-09-02
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
- CVE-2020-13851CRITICALCVSS 8.8EG 9.02020-06-11
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
- CVE-2020-13917CRITICALCVSS 9.8EG 9.82020-07-28
rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R7…
- CVE-2020-13919CRITICALCVSS 9.8EG 9.82020-07-28
emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R7…
- CVE-2020-13925CRITICALCVSS 9.8EG 9.82020-07-14
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have th…
- CVE-2020-13976HIGHCVSS 8.8EG 8.82020-06-09
An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: s…
- CVE-2020-13978HIGHCVSS 7.2EG 7.22020-06-09
Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary OS commands via the Theme Module by visiting the admin/index.php?id=themes&action=edit_ch…
- CVE-2020-14072CRITICALCVSS 9.8EG 9.82020-06-29
An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin scripts.
- CVE-2020-14075HIGHCVSS 8.8EG 8.82020-06-15
TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action pppoe_connect, ru_pppoe_connect, or dhcp_connect with the key wan_ifname (or wan0_dns), allowing an authenticated user to run arbit…
- CVE-2020-14081HIGHCVSS 8.8EG 8.82020-06-15
TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action send_log_email with the key auth_acname (or auth_passwd), allowing an authenticated user to run arbitrary commands on the device.
- CVE-2020-14144CRITICALCVSS 7.2EG 9.02020-10-16
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that the dangerousness of this feature shoul…
- CVE-2020-14162HIGHCVSS 7.8EG 7.82020-07-30
An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an attacker to obtain root access via shell metacharacters to this …
- CVE-2020-14293HIGHCVSS 7.5EG 7.52020-10-02
conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface).
- CVE-2020-14324CRITICALCVSS 9.1EG 9.12020-08-11
A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversion host through Infr…
- CVE-2020-14342HIGHCVSS 4.4EG 7.02020-09-09
It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, coul…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →